- Cisco Releases Security Advisories for Multiple Products
- Atlassian Releases Security Advisory for Confluence Data Center and Server
- VMware Releases Advisory for VMware Tools Vulnerabilities
- Apple Releases Security Updates for iOS and iPadOS
- VMware Releases Security Advisory for vCenter Server
- Mozilla Releases Security Advisories for Multiple Products
Cisco Releases Security Advisories for Multiple Products
Situation: Problem: Implication: Need: Additional Resources: Cisco Releases Security Advisories for Multiple Products: Cisco Firepower Management Center Software Command Injection Vulnerability: Cisco Identity Services Engine Command Injection Vulnerabilities: Cisco Identity Services Engine Vulnerabilities: Cisco Firepower Threat Defense Software for Cisco Firepower 2100 Series Firewalls Inspection Rules Denial of Service Vulnerability: Cisco Firepower Threat Defense Software ICMPv6 with Snort 2 Denial of Service Vulnerability: Cisco Firepower Threat Defense Software and Firepower Management Center Software Code Injection Vulnerability: Cisco Firepower Management Center Software Log API Denial of Service Vulnerability: Cisco Firepower Management Center Software Command Injection Vulnerabilities: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Denial of Service Vulnerability: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software ICMPv6 Message Processing Denial of Service Vulnerability:
|
Atlassian Releases Security Advisory for Confluence Data Center and Server
Situation: Problem: Implication: Need: 7.19.16 Additional Resources: Atlassian Releases Security Advisory for Confluence Data Center and Server: CVE-2023-22518 – Improper Authorization Vulnerability In Confluence Data Center and Server: |
VMware Releases Advisory for VMware Tools Vulnerabilities
Situation: Problem: Local privilege escalation vulnerability in VMware Tools (macOS) (CVE-2023-34057) SAML Token Signature Bypass vulnerability in VMware Tools (CVE-2023-34058) Implication:
CVE-2023-34058:
Need: Additional Resources: VMware Releases Advisory for VMware Tools Vulnerabilities VMSA-2023-0024 |
Apple Releases Security Updates for iOS and iPadOS
Situation: Problem: Implication: A buffer overflow may result in arbitrary code execution (CVE-2023-42824) Need: Additional Resources: Apple Releases Security Updates for iOS and iPadOS: https://www.cisa.gov/news-events/alerts/2023/10/06/apple-releases-security-updates-ios-and-ipados About the security content of iOS 17.0.3 and iPadOS 17.0.3: |
VMware Releases Security Advisory for vCenter Server
Situation: Problem: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8 (CVE-2023-34048). vCenter Server contains a partial information disclosure vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.3 (CVE-2023-34056). Implication: A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data (CVE-2023-34056). Need: Additional Resources: VMware Releases Security Advisory for vCenter Server: https://www.cisa.gov/news-events/alerts/2023/10/26/vmware-releases-security-advisory-vcenter-server VMSA-2023-0023: |
Mozilla Releases Security Advisories for Multiple Products
Situation: Problem: Implication: Need: Additional Resources: Mozilla Releases Security Advisories for Multiple Products Security Vulnerabilities fixed in Firefox for iOS 119 Security Vulnerabilities fixed in Thunderbird 115.4.1 |